Live data from Hacker News

Can someone please explain whether Cloudflare blackmailed Canonical?

flyingpenguin.com

141–150 of 182 posts

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#141
post #111

Earlier quoted context omitted.

So "big companies only, absolutely no anonymous sign-ups" should be the only ones able to put stuff on the internet without fearing that a random teenager can take your site offline for days just because they're bored?

No. Nobody said that. Cloudflare should simply enforce basic rules, like "don't run a cybercrime storefront", rather than letting criminal operations like this proliferate.

Plausible deniability is all they really need. Asking companies not to make money in very likely to be legal ways will never work. If these people are really doing illegal business in plain sight it should be easy for law enforcement to catch them.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#142
There's not even any proof Beamed was responsible for the attack in the article--it's all speculation.

"Anonymous person on the internet claiming " is proof of nothing.

It's just as likely someone claimed they used Beamed to try to get a competing service taken down or direct attention elsewhere.

Don't get my wrong, Beamed looks like a scummy booter service with no legal purpose.

However, claiming companies should deplatform sites based on speculation is, imo, a very dangerous precedent.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#143
post #5

Earlier quoted context omitted.

Yeah, probably not - because they don't explicitly have to, as outlined in the post. The very architecture of CF's services essentially enables "blackmail as a service" in the sense that, CF protects the attacker and essentially creates a coercive environment in which the victim "has" to pay CF to protect them from... the very attacker that CF protects.

> and essentially creates a coercive environment This is the part that's wrong. CF is not creating the fact that sites are vulnerable to DDoS, and these attacks would happen even if the sites were kicked off. If some guys are going around slashing tires, would we demand that tire repair shops not sell to them? Would we say it's blackmail because the tire shop sells to anyone, and selling tires to them "creates a coer…

A tire repair shop that also hosted a the National Tire Slashing Club for free in the back?

I think it's fair to assume that would cause some reactions.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#144

Earlier quoted context omitted.

> and essentially creates a coercive environment This is the part that's wrong. CF is not creating the fact that sites are vulnerable to DDoS, and these attacks would happen even if the sites were kicked off. If some guys are going around slashing tires, would we demand that tire repair shops not sell to them? Would we say it's blackmail because the tire shop sells to anyone, and selling tires to them "creates a coer…

A tire repair shop that also hosted a the National Tire Slashing Club for free in the back? I think it's fair to assume that would cause some reactions.

That gets confusing because it sounds like a special thing they're doing in addition to their main function.

If the back of the store was a convention center that allowed basically any small club to use it for free, and of their many thousands of hosted clubs one or two were focused around tire slashing, that wouldn't cause the same reactions.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#145
post #139
post #123

Earlier quoted context omitted.

How? Their sign-up flow would have to change dramatically. It might even become a process that is internally "expensive". There is likely one or more managers in charge of this decision and they don't want it. Additionally the current universe rewards the current situation (for them)

This is called KYC and is a standard part of operating a financial service. Seems to me like it should be part of internet infrastructure services as well. And, I thought, in some cases already is?

... and financial services companies huge and small still go out of their way to help their clients move money around in a myriad of ways, because it's very lucrative and there are so many loopholes and ways to obscure things. Offloading the responsibilities of law enforcement and regulatory bodies to private companies makes things worse for everybody. Providing non-crime services to criminals should not be a crime any more than selling a candy bar to a criminal is. As long as you aren't actively aiding or covering up for a crime, not reporting criminal activity is not even a crime in many areas, and if KYC can effectively identify criminals, law enforcement should be able to do it themselves.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#146
post #55

Earlier quoted context omitted.

Most companies have TOS that include not damaging or attacking the company itself. The advertised service attacks Cloudflare explicitly. It seems very straightforward that this would violate any reasonable TOS. edit: and here it is straight from their TOS https://www.cloudflare.com/en-ca/website-terms/ "7. PROHIBITED USES As a condition of your use of the Websites and Online Services, you will not use the Websites or…

cloudflare is not hosting the infrastructure doing the actual attacks. the attack is coming from residential proxy servers, not from the webpage being hosted by cloudflare, which is just a marketing page and a login portal. that clause is not really applicable. in any case, its not a question of whether cloudflare can remove a website. of course they can, for whatever reason they want. its a question of whether we wa…

> the webpage being hosted by cloudflare, which is just a marketing page and a login portal

thus being used for illegal and harmful activities right?

> Cloudflare retains the right (but not the obligation) to block content from its Distributed Web Gateway that Cloudflare determines (in its sole discretion) to be illegal, harmful

Not that I have any hope for TOS violation claims. I've learned early on in life that people generally don't care in life if you violate rules they invented if they're not impacted themselves. They do care if they violate someone else's rules and there is a chance of repercussions. There are exceptions, quite a few hosting companies in fact, but Cloudflare so far hasn't acted like a party that has the good of the web in its interest (even when strictly speaking of whom they offer services to despite them doing harm). Just wanted to point out that the cited clause, assuming it is correct as stated above, could be applied at Cloudflare's discretion if they so wished

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#147
post #146

Earlier quoted context omitted.

cloudflare is not hosting the infrastructure doing the actual attacks. the attack is coming from residential proxy servers, not from the webpage being hosted by cloudflare, which is just a marketing page and a login portal. that clause is not really applicable. in any case, its not a question of whether cloudflare can remove a website. of course they can, for whatever reason they want. its a question of whether we wa…

> the webpage being hosted by cloudflare, which is just a marketing page and a login portal thus being used for illegal and harmful activities right? > Cloudflare retains the right (but not the obligation) to block content from its Distributed Web Gateway that Cloudflare determines (in its sole discretion) to be illegal, harmful Not that I have any hope for TOS violation claims. I've learned early on in life that peo…

>thus being used for illegal and harmful activities right?

neither the login portal page nor the marketing page are illegal.

>Cloudflare so far hasn't acted like a party that has the good of the web in its interest

for a lot of reasons, i generally agree with this statement. however, for this specific reason (maintaining a content-neutral approach, instead of playing content-police), i could not disagree more. cloudflare making hosting decisions based on the legal content of your site would be a huge disservice to the internet.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#148

Earlier quoted context omitted.

In The Before Times, there were very few problematic DDOS operations because... they would all DDOS one another offline. Websites, control infrastructure, anything. DDOS protection services were provided by companies like Akamai; call for pricing, big companies only, absolutely no anonymous sign-ups. Cloudflare revolutionised the industry by providing free DDOS protection to anyone, including DDOS-for-hire services.…

It's been a well known story around Cloudflare from the beginning that they protect booters and other cybercrime actors just like any other (paying or non-paying) customer. If you report the DDoS-for-hire actors that offer their services on forums where such things are offered openly, they reply with a template that freely interpreted say something along the lines that they can do nothing and who is a crimininal is .…

[deleted]

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#149

"Renting attack capacity from [cloudflare]" is inaccurate as I understand things. That group hosts their site behind cloudflare but I have not seen anyone claim that cloudflare's infra is used for the attacks. This whole article seems conflate hosting an informational site run by the attackers and hosting the attack itself.

In The Before Times, there were very few problematic DDOS operations because... they would all DDOS one another offline. Websites, control infrastructure, anything. DDOS protection services were provided by companies like Akamai; call for pricing, big companies only, absolutely no anonymous sign-ups. Cloudflare revolutionised the industry by providing free DDOS protection to anyone, including DDOS-for-hire services.…

You mean if CloudFlare didn’t protect DDOSers, CloudFlare wouldn’t be able to provide as much service to the victims ?

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#150
post #61

With this kind of logic we can blame keyboard manufacturers for the illegal things their products wrote.

This is a service, not a device sale. Continuing to provide a service to an organization that is using it to support criminal activity is very different and terminating clients for illegal activity is not controversial.

>At Beamed.su, we provide a professional stresser panel intended for security researchers and network administrators to test their own assets.

It's the customers of Beamed doing the illegal activity and not Beamed themselves.

Post reply on HN